Information disclosure in APM Clients and BIG-IP APM - CVE-2021-23002
Published: March 22, 2021
Vulnerability identifier: #VU51601
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23002
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to the session ID is visible in the arguments of the f5vpn.exe command when VPN is launched from the browser on a Windows system. A remote administrator on the local network can view the session ID.
Affected software
APM Clients
BIG-IP APM
BIG-IP APM
How to mitigate CVE-2021-23002
Install updates from vendor's website.
APM Clients - addressed in versions 7.1.8.5, 7.1.9.8, 7.2.1.1
BIG-IP APM - addressed in versions 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP APM - addressed in versions 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1